Legal

Data Processing Agreement

Effective date: May 19, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between OnPoint (“Processor”) and the customer organization (“Controller”) and governs OnPoint's processing of Personal Data on behalf of the Controller.

1. Definitions

"Controller" means the customer organization that determines the purposes and means of processing Personal Data. "Processor" means OnPoint, which processes Personal Data on behalf of the Controller. "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection law. "Processing" has the meaning given by applicable data protection law and includes storing, retrieving, using, disclosing, and deleting Personal Data. "Security Incident" means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

2. Roles and Scope

The Controller submits Personal Data to the Service for the purpose of operating a knowledge management platform for authorized users within its organization. OnPoint acts as a Processor with respect to that Personal Data and will process it only on documented instructions from the Controller, except where required by law.

3. Processing Details

Subject matter: Operation of the OnPoint knowledge management platform. Duration: For the term of the Controller's subscription, plus any retention period required by law or agreed in writing. Nature and purpose: Storing, organizing, retrieving, and managing documents and knowledge assets on behalf of the Controller's authorized users. Generation of derived insights, network intelligence, contact relationship mapping, and sales recommendations from Customer Data, made available only to the Controller and its authorized users. Type of Personal Data: Names, email addresses, IP addresses, and activity logs of authorized users. Where the Controller's authorized users elect to import or sync them, contact records (names, email addresses, phone numbers, titles, employer, and related professional metadata) and the content of communications submitted to the Service. Categories of data subjects: The Controller's employees, contractors, and authorized external users. Where applicable, third-party contacts of the Controller (for example, customers, prospects, vendors, and other business contacts whose information the Controller chooses to store in the Service).

4. Processor Obligations

OnPoint agrees to: (a) Process Personal Data only on documented instructions from the Controller; (b) Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations; (c) Implement appropriate technical and organizational security measures (see Section 7); (d) Assist the Controller in responding to requests from data subjects exercising their rights; (e) Assist the Controller in ensuring compliance with data breach notification obligations; (f) Delete or return all Personal Data upon termination of the agreement, at the Controller's election; (g) Make available all information necessary to demonstrate compliance with this DPA.

5. Controller Obligations

The Controller is responsible for: (a) ensuring it has a lawful basis for providing Personal Data to OnPoint; (b) providing accurate and timely instructions to OnPoint regarding the processing of Personal Data; and (c) ensuring that data subjects have been informed about the processing in accordance with applicable law.

6. Sub-Processors

OnPoint engages the following sub-processors. The Controller provides general authorization for OnPoint to engage sub-processors subject to the conditions in this section. Supabase, Inc. — database, authentication, and file storage (United States) Vercel, Inc. — application hosting (United States) Resend, Inc. — transactional email delivery (United States) Anthropic PBC — AI-assisted content processing (United States) OnPoint will: (a) impose data protection obligations equivalent to those in this DPA on each sub-processor; (b) remain fully liable to the Controller for the performance of sub-processors; and (c) notify the Controller at least 30 days before adding or replacing a sub-processor, providing the Controller an opportunity to object.

7. Security Measures

OnPoint implements and maintains the following technical and organizational measures: Encryption: All data is encrypted in transit using TLS 1.2 or higher. Database data is encrypted at rest. Access controls: Row-level security is enforced on all database tables. Administrative access is restricted to authorized personnel. Authentication: Multi-factor authentication is available and encouraged for all users. API access is authenticated via scoped, bcrypt-hashed keys. Audit logging: All access and modification events are logged with user identity, timestamp, and IP address. Vulnerability management: Dependencies are scanned for known vulnerabilities in CI/CD pipelines. Incident response: OnPoint maintains an incident response plan and will notify the Controller of confirmed Security Incidents within 72 hours of becoming aware.

8. Security Incident Notification

In the event of a confirmed Security Incident affecting the Controller's Personal Data, OnPoint will: (a) notify the Controller without undue delay and in any event within 72 hours of becoming aware; (b) provide information about the nature and scope of the incident, the categories and approximate number of records affected, likely consequences, and measures taken or proposed; and (c) cooperate with the Controller's investigation and remediation efforts.

9. Data Subject Rights

To the extent technically feasible and consistent with OnPoint's obligations under applicable law, OnPoint will assist the Controller in fulfilling data subject requests for access, portability, correction, deletion, or restriction of processing. The Controller remains responsible for determining whether such requests are valid and for communicating with data subjects.

10. International Data Transfers

Personal Data processed under this DPA may be transferred to and stored in the United States. Where the Controller is subject to EU or UK data protection law, such transfers are conducted under the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor), which are incorporated into this DPA by reference. A copy of the applicable SCCs is available on request.

11. Audits

The Controller may, upon reasonable notice and at its own expense, audit OnPoint's compliance with this DPA no more than once per calendar year, or following a confirmed Security Incident. OnPoint may satisfy audit obligations by providing up-to-date certifications or reports from qualified third-party auditors.

12. Term and Termination

This DPA is effective for the duration of the Controller's use of the Service. Upon termination, OnPoint will, at the Controller's instruction, delete or return all Personal Data within 30 days and certify in writing that deletion has been completed.

13. Governing Law

This DPA is governed by the same law as the underlying Terms of Service between the parties. Where EU or UK GDPR applies, the parties agree to the jurisdiction of the courts of Ireland (for EU matters) or England and Wales (for UK matters) for any disputes relating to this DPA.

14. Contact

To execute a signed copy of this DPA or for questions about data processing, contact privacy@ontel.co.